---
titel: "IT compliance in Switzerland and the EU: rules and laws · SACOSI"
url: https://sacosi.ch/en/regulation
seite: /en/regulation
stand: 2026-09-24
beschreibung: "Which IT regulations apply to Swiss companies? ISO 27001, ISO 9001, TISAX, EU MDR, FADP, GDPR, NIS2 and the EU AI Act, by industry and market."
---

> Knowledge version of the page https://sacosi.ch/en/regulation. It contains the full text, including what is shortened or collapsible on the page itself. Publisher: SACOSI, Situational Awareness Consulting by Ivo Schönberner, Zürich.

# Which IT regulations apply to your company?

**Short answer:** That depends on three things: your industry, your markets and your customers. A Swiss company operates under the Swiss Federal Act on Data Protection (FADP), and, with customers in the EU, also under the GDPR. EU laws such as NIS2 usually affect Swiss companies indirectly, through EU establishments or customers in the supply chain. Standards such as ISO 27001, ISO 9001 or TISAX are voluntary but are demanded contractually. This page classifies the most important rules and does not replace legal advice.

## What applies in Switzerland, what applies in the EU?

All 22 rules in the knowledge base in one list: filter by scope of application, industry, bindingness and type, sort by name, next deadline or bindingness. Clicking on a rule shows how it applies in Switzerland and in the EU. As of: September 2026.

For your own profile, use the Regulatory Check. Whether a rule applies in your specific case is clarified by the situation picture.

## Conformant or certified?

Conformant does not mean certified — but in customer due-diligence reviews, it makes a real difference.

- **Conformity** means: you meet the requirements and can demonstrate it, with documentation, approvals and records.
- **Certification** means: an accredited body has audited and confirmed it.
- **In practice,** customers ask about both in supplier assessments and security questionnaires. Demonstrable conformity shortens these reviews considerably, even without a certificate.

## How does a compliance roadmap come about?

From the situation picture: first clarify which rules actually apply, then implement them in order of risk and business impact.

- **Classify:** industry, markets, customers, products and data yield the list of obligations.
- **Prioritise:** what is required by law, what customers demand, what investors expect.
- **Build in:** requirements become part of the processes, not a folder on the side.
- **Evidence:** versioned, approved, in an auditable system. IT am Main works the same way, certified to ISO 27001 and ISO 9001 since January 2025.

This overview is a professional assessment, not legal advice. The legal assessment of any individual case belongs in a proper legal review.

## Sources

Information as of: 24 September 2026.

- [Federal Act on Data Protection (FADP), SR 235.1, in force since 1 September 2023](https://www.fedlex.admin.ch/eli/cc/2022/491/de)
- [Regulation (EU) 2016/679, General Data Protection Regulation, Articles 3 and 27](https://eur-lex.europa.eu/eli/reg/2016/679/oj)
- [Directive (EU) 2022/2555 (NIS2), in particular Articles 21 and 26](https://eur-lex.europa.eu/eli/dir/2022/2555/oj)
- [BSI: NIS2 Implementation Act enters into force, press release of 5 December 2025](https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html)
- [Federal Office for Cybersecurity (BACS): reporting obligation for cyberattacks on critical infrastructure](https://www.bacs.admin.ch/de/meldepflicht)
- [Regulation (EU) 2024/1689 (AI Act), as amended by Regulation (EU) 2026/1744, published on 24 July 2026](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)
- [Federal Chancellery: Artificial intelligence, status of Swiss regulation](https://www.bk.admin.ch/de/ki)
- [Regulation (EU) 2017/745 on medical devices](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
- [Swissmedic: New medical device regulation as of 26 May 2021](https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html)
- [European Commission: Cyber Resilience Act, reporting obligations](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting)
- [Electricity Supply Ordinance (StromVV), amendment AS 2024 282 (ICT minimum standard, Article 5a)](https://www.fedlex.admin.ch/eli/oc/2024/282/de)
- [FOCA: EU regulations on information security (Part-IS)](https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is)
- [ENX Association: TISAX](https://enx.com/tisax)

## Questions about regulation.

### Does NIS2 apply to Swiss companies?

Not directly. NIS2 is an EU directive. It affects Swiss companies through an establishment in the EU, because EU customers must demonstrate the security of their supply chain and pass this requirement on contractually, or if a company offers certain digital services such as cloud or managed services in the EU. In that case, a representative in the EU must be appointed.

### Since when has the new Swiss Data Protection Act applied?

Since 1 September 2023. It applies to all companies that process personal data in Switzerland. Anyone serving customers in the EU must also observe the GDPR.

### Does the EU AI Act apply to Swiss companies?

Yes, if they place AI systems on the market in the EU or if the output of their AI systems is used in the EU. The obligations have applied in stages since February 2025. The obligations for high-risk systems apply from December 2027, for AI in regulated products from August 2028.

### What is the difference between ISO 27001 and TISAX?

ISO 27001 is an international standard for information security management systems, with a certificate. TISAX is an assessment procedure used by the automotive industry, based on the VDA ISA catalogue, with a label instead of a certificate, and is required contractually by vehicle manufacturers.

### Does the EU MDR apply in Switzerland?

In Switzerland, the Medical Devices Ordinance (MedDO) applies, with Swissmedic as the supervisory authority. For access to the EU market, the EU MDR applies. Since 26 May 2021, the EU has treated Switzerland as a third country for medical devices, so Swiss manufacturers need an authorised representative in the EU.

### Must a start-up be certified to ISO 27001?

Not by law. But corporate customers, tenders and investors often ask about it. It makes sense to build processes early on so that certification later is a small step, not a rebuild.

## Which rules apply to you?

Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile.

CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English
